CVE-2021-26085: Atlassian Confluence Server Pre-Authorization Arbitrary
Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability. Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
- CISA KEV-listed (remediation due 2022-04-18)
- used in ransomware campaigns
- EPSS 94.0% (99.9% percentile)